Show filters
246 Total Results
Displaying 231-240 of 246
Sort by:
Attacker Value
Unknown

CVE-2008-4749

Disclosure Date: October 27, 2008 (last updated October 04, 2023)
Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.
0
Attacker Value
Unknown

CVE-2008-4750

Disclosure Date: October 27, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allows remote attackers to execute arbitrary code via a long LogFile property.
0
Attacker Value
Unknown

CVE-2008-3432

Disclosure Date: October 10, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.
0
Attacker Value
Unknown

CVE-2008-4101

Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.
0
Attacker Value
Unknown

CVE-2008-3294

Disclosure Date: July 24, 2008 (last updated October 04, 2023)
src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.
0
Attacker Value
Unknown

CVE-2008-2712

Disclosure Date: June 16, 2008 (last updated October 04, 2023)
Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3) xpm.vim, (4) gzip_vim, and (5) netrw. NOTE: the originally reported version was 7.1.314, but the researcher actually found this set of issues in 7.1.298. NOTE: the zipplugin issue (originally vector 2 in this identifier) has been subsumed by CVE-2008-3075.
0
Attacker Value
Unknown

CVE-2007-5445

Disclosure Date: October 14, 2007 (last updated October 04, 2023)
Buffer overflow in the DB Software Laboratory VImpX (VImpAX1) ActiveX control in VImpX.ocx 4.7.3.0 allows remote attackers to execute arbitrary code via a long RejectedRecordsFile parameter, a different vector than CVE-2007-2667.
0
Attacker Value
Unknown

CVE-2007-2953

Disclosure Date: July 31, 2007 (last updated October 04, 2023)
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
0
Attacker Value
Unknown

CVE-2007-2667

Disclosure Date: May 14, 2007 (last updated October 04, 2023)
Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long LogFile parameter.
0
Attacker Value
Unknown

CVE-2007-2438

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.
0